Regulatory compliance
851 rows from 237 repositories
Frameworks with an auditor and a penalty behind them.
What Regulatory compliance skills agree on
111 skill files read, by 117 of the 175 authors on this shelf whose files we hold, 2026-09-06
Counted by distinct author, so one author publishing three of these counts once. Where a claim sits in fewer files than authors, that is said: a claim held by forty authors across three files is one file people copied, not forty people who agreed. Near-identical wordings are grouped and the other wordings are shown, so the grouping is yours to check.
What they tell the agent to do
- Prefer opaque internal IDs over direct identifiers13 of 117 in 5 files
- Require redaction or a non-PHI event model13 of 117 in 5 filesalso worded as Prefer redaction or non-PHI event models; Require de-identification or non-PHI event models
- Start with healthcare-phi-compliance for concrete implementation rules13 of 117 in 5 filesalso worded as Start with the PHI compliance skill's implementation rules; Start with healthcare-phi-compliance for PHI implementation rules
- Escalate to healthcare-reviewer when patient safety or clinical workflows are affected13 of 117 in 5 filesalso worded as Escalate to the healthcare reviewer for patient safety impact; Escalate to healthcare-reviewer for patient-safety or clinical impact
- Require authenticated access, scoped authorization, and audit trails for PHI13 of 117 in 5 filesalso worded as Require authenticated, authorized, and audited PHI access; Require authenticated scoped access and audit trails for PHI
- Treat third-party providers as blocked until BAA status is clear13 of 117 in 5 filesalso worded as Block third-party providers until BAA status is clear; Treat third-party providers as blocked until BAA is clear
- Assume patient messages may contain PHI9 of 117 in 4 filesalso worded as Assume user messages may contain PHI; Assume messages may contain PHI
- Apply HIPAA decision gates8 of 117 in 3 filesalso worded as Apply HIPAA-specific decision gates to the task; Apply HIPAA decision gates before handling data
- Verify BAA coverage before sending PHI to any provider8 of 117 in 3 filesalso worded as Verify BAA coverage before PHI reaches any vendor; Verify vendors have BAA before receiving PHI
- Give users only the smallest PHI slice needed7 of 117 in 2 filesalso worded as Limit users to the smallest PHI fragment needed
- Encrypt data at rest and in transit7 of 117also worded as verify encryption at rest and in transit; Encrypt PHI in transit and at rest
- Make PHI read, write, and export events auditable6 of 117 in 3 files
- Classify whether the data is PHI6 of 117 in 3 filesalso worded as Confirm whether data qualifies as PHI; classify data as PHI before handling it
- Limit access to the minimum necessary scope6 of 117 in 3 filesalso worded as Limit access to the minimum necessary PHI scope; Limit PHI access to the minimum necessary
- Block designs sending PHI to unapproved analytics vendors5 of 117 in 2 files
What they tell it not to do
- Never send PHI to vendors without a BAA14 of 117 in 6 filesalso worded as Never send PHI to vendors without a BAA; Never send PHI to providers lacking a BAA
- Never place PHI in logs, analytics, prompts, or errors13 of 117 in 5 filesalso worded as Never place PHI in logs, analytics, prompts, or errors; Never place PHI in logs, analytics, crash reports, or prompts
- Never expose PHI in URLs, storage, or screenshots13 of 117 in 5 filesalso worded as Never expose PHI in URLs, storage, or screenshots; Never expose PHI in URLs, browser storage, or screenshots
- Do not present output as legal advice or certification5 of 117also worded as Never present output as a definitive legal ruling; Do not present the output as legal advice
- Never treat addressable specifications as optional4 of 117 in 1 file
- Never treat 2025 NPRM proposals as in force4 of 117 in 1 file
- Never let ePHI flow before a BAA is signed4 of 117 in 1 file
- Never log card data4 of 117also worded as Do not log PII or cardholder data; Never log plaintext card numbers
- Never provide legal advice4 of 117also worded as don't provide jurisdiction-specific legal advice; Do not provide legal advice
- Do not justify budget with industry benchmarks3 of 117 in 1 file
What they expect to be installed
- healthcare-phi-compliance13 of 117 in 5 files
- healthcare-reviewer13 of 117 in 5 files
- security-review12 of 117 in 4 files
- grep7 of 117
- python6 of 117 in 4 files
- Terraform5 of 117
- Python 3.8+4 of 117 in 1 file
- PrivacyImpactAssessmentEngine4 of 117 in 1 file
- HHS Security Risk Assessment (SRA) Tool4 of 117 in 1 file
- NIST SP 800-304 of 117 in 1 file
What they ask it to produce
- Data flow diagram10 of 117 in 7 filesalso worded as Data flow map
- Remediation plan9 of 117 in 6 filesalso worded as Remediation roadmap; Remediation plan with effort estimates
- GDPR compliance report6 of 117 in 2 files
- CCPA compliance report5 of 117 in 2 filesalso worded as Compliance reports
- Gap table and remediation-priority list5 of 117 in 2 filesalso worded as Remediation priority list
- Gap analysis with remediation plan5 of 117 in 3 filesalso worded as Gap and remediation recommendations; Remediation plan entries per gap
- Gap analysis5 of 117also worded as Gap analysis report; Gap analysis table
- Processing activity inventory4 of 117 in 1 file
When Regulatory compliance authors say to reach for one
The situations these authors wrote into their own files, counted out of the same 117 authors, with the skills that name each one
- Assessing HIPAA exposure in logging, analytics, prompts, or storage13 of 117 in 5 files
- Hipaa compliance
- and 3 more on this shelf
- User asks about compliance or regulatory requirements8 of 117
- Compliance tracking
- Compliance
- and 3 more on this shelf
- Preparing for regulatory audits6 of 117 in 3 files
- Task explicitly mentions HIPAA, PHI, or BAAs5 of 117 in 2 files
- Hipaa compliance
- and 3 more on this shelf
- Designing systems where minimum necessary access matters5 of 117 in 2 files
- Hipaa compliance
- and 3 more on this shelf
How Regulatory compliance skills are built
676 skill directories by 185 authors, read from their repositories’ own file trees 2026-08-05
The middle bundle among those shipping files is 5 files, 43.9 KB beside SKILL.md
Counted by distinct author, same as above, so one author publishing forty template copies counts once. SKILL.md itself is not counted as a file, so a single-file skill is one where that file is the whole skill.
The shape
- SKILL.md is the whole skill68 of 185 authors, 271 of 676 skills
- files ship beside it117 of 185 authors, 405 of 676 skills
- executable scripts ship inside40 of 185 authors, 177 of 676 skills
The folders they converge on
- references/80 of 185 authors, 282 of 676 skills
- scripts/38 of 185 authors, 163 of 676 skills
- assets/26 of 185 authors, 97 of 676 skills
- examples/11 of 185 authors, 23 of 676 skills
- resources/9 of 185 authors, 13 of 676 skills
- agents/7 of 185 authors, 39 of 676 skills
patrickstigler/claude-skill-it-recht-dsgvo Skill
no license17★Ein Claude Skill für rechtliche Ersteinschätzungen im deutschen IT-Recht und Datenschutzrecht (DSGVO/BDSG).
wuemaikblume/dsgvo-skills/claude/skills/dsgvo-auth-and-logging Skill
no license11★ repoDSGVO Compliance Skills für Claude AI / Claude Code — DACH-fokussierte Best-Practice-Sammlung für Drittlandtransfer (Art. 44-49) mit US-CLOUD-Act-Hinweis
ark-forge/mcp-eu-ai-act/io.github.ark-forge/mcp-eu-ai-act MCP server
11★ repoEU AI Act + GDPR compliance scanner. One call, no arguments, 10 seconds. 22 AI frameworks detected.
Saudi Regulatory Compliance Claude Skill
ibnsawad/Saudi-Regulatory-Compliance-Claude-Skill Skill
no license8★Expert-level Claude Skill for Saudi regulatory compliance — NCA ECC, SAMA-CSF, PDPL, CST and more.
austinsonger/GRC-Mapping-Analyst/skills/strm-mapping Skill
no license4★ repoGRC Mapping Analyst is a NIST IR 8477-based toolkit for AI-assisted cybersecurity crosswalks, producing deterministic set-theory mappings (equal, subset_of, superset_of, intersects_with, not_related) and 12-column STRM CSV outputs across frameworks, regulations, and control catalogs.
sundsoffice-tech/ai-audit-trail/io.github.sundsoffice-tech/ai-audit-trail MCP server
4★ repoTamper-evident audit trails for AI agents — Ed25519-signed, hash-chained, EU AI Act ready.
cyber-sorted/skills-pro/cybersorted Skill
no license3★ repoProfessional security and enterprise architecture advisory skills for Claude Code
abk1969/ai-act-skills/skills/ai-act-compliance Skill
3★ repoMulti-platform agent skills (Claude Code + Gemini CLI + OpenAI Codex) for EU AI Act compliance, anchored on ISO/IEC 42001 (AIMS) and ISO/IEC 27090 (AI cybersecurity). Citation-grade. Decision-support, not legal advice.
hackIDLE/nist-cybersecurity-skills/skills/nist-cybersecurity-skills Skill
3★ repoClaude Code plugin with comprehensive NIST cybersecurity framework references (SP 800-53, 800-171, CSF 2.0, and more)
PCI DSS v4.0.1 Compliance Checker
shyshlakov/pci-dss-mcp/io.github.shyshlakov/pci-dss-mcp MCP server
3★ repoPCI DSS v4.0.1 compliance scanner for Go payment services, delivered as an MCP server
Aidress skill find verified regulatory compliance agent
Aidress-ai/aidress-skill-find-verified-regulatory-compliance-agent Skill
2★Find a Verified Regulatory Compliance Agent. Agent discovery, trust verification, and capability routing powered by Aidress — the coordination registry for autonomous AI agents. Use for legal agent discovery, trust verification, and capability routing — via Aidress (https://api.aidress.ai).
uttej-badwane/secure-cloud-prompt-engineering/skills/iac-security-review Skill
2★ repoSecurity-focused prompt library and Claude Code skill for automated IaC security reviews. Covers Terraform, Kubernetes, Docker, Ansible, CloudFormation, and CI/CD pipelines. Compliance mapping to CIS, NIST 800-53, PCI-DSS, SOC2, HIPAA, and GDPR.
vaquarkhan/compliance-agent-skills/skills/access-control-identity-audit Skill
2★ repo30 Agent Skills for deterministic USA compliance auditing of AI agents — HIPAA, NIST AI RMF, FERPA, COPPA, PCI-DSS, SOC 2, FedRAMP, CMMC, GLBA, privacy & GDPR. Presidio PHI redaction, MCP templates, Pydantic AI, VS Code & JetBrains plugins.
grcwarlock/compliance-as-code/skills/iso-27001 Skill
2★ repoOpen-source agent skills, agents, and reference connectors for compliance engineers. SOC 2, ISO 27001, NIST 800-53.
vllnt/skills/regulatory-guard Skill
1★ repoOpen-source agent skills published by vllnt. Compatible with Claude Code, OpenCode, Codex, Pi, Cursor, Windsurf, and any runtime that loads skills from Markdown directories.
tersignhq/skills/tersign-evidence Skill
1★ repoOfficial Tersign agent skills — produce, verify, and submit counter-signed evidence from any agent framework (Claude Code, MCP, Internet Court).
ravipalwe/design-skills/skills/fintech-ux Skill
1★ repoDesign skills for AI agents — roast-my-ui, de-slop, fix-contrast & more. Senior design judgment with computed receipts. Install: npx skills add ravipalwe/design-skills
Akhilgovind02/india-regulatory-mcp/io.github.Akhilgovind02/india-regulatory-mcp MCP server
1★ repoSearch RBI & SEBI circulars, master directions and regulations. Offline SQLite index, no API keys.
Orbit Sentinel — Space Regulatory Filings
viventine-space/orbit-sentinel-mcp/io.github.Viventine-Space/orbit-sentinel-mcp MCP server
1★ repoSearch 950K+ space regulatory filings from FCC, ITU, UNOOSA, FAA-AST: entities, spectrum, dossiers.
cyanheads/nist-nvd-mcp-server/io.github.cyanheads/nist-nvd-mcp-server MCP server
1★ repoSearch and audit NIST NVD CVEs by keyword, severity, CWE, CISA KEV status, and CPE.
dhanushs1912-svg/agent-receipts-mcp/io.github.dhanushs1912-svg/agent-receipts-mcp MCP server
1★ repoEU AI Act-ready audit trail: signed, tamper-evident receipts proving what your AI agents did.
kajaril/sovereignty-scan-mcp/io.github.kajaril/sovereignty-scan-mcp MCP server
1★ repoEU AI Act sovereignty scanning. Provider residency, registration status, audit trail support.
uchit/mcp-regulated-ai-compliance/io.github.uchit/mcp-regulated-ai-compliance MCP server
1★ repoRegulated-industry AI compliance: EU AI Act, APRA, NIST AI RMF, ISO 42001, AU AI Safety.
Build-Flow-Labs/sox-itgc-claude-skill/sox-itgc Skill
0★ repoExpert SOX 404 ITGC compliance guidance as a Claude Skill. PCAOB AS 2201, COSO 2013, Big Four audit methodology, plus a Build Chain of Custody pattern for modern engineering.
EliasAli0720/HIPAA-agent-skill/skills/hipaa-ai-compliance Skill
0★ repoHIPAA compliance skills for AI coding agents (Claude Code, Codex, Cursor, Gemini). 10 senior-grade skills: scoping, app dev, websites, AI/LLM, code review + PHI scanner, risk analysis, breach response, BAAs, de-identification, compliance programs. Exact 45 CFR citations, OCR enforcement through 2026.
Thilina099/rubysky-skills/skills/hipaa-marketing-check Skill
0★ repoFree Claude Skills for local service businesses, healthcare orgs, and nonprofits. Lead follow-up, HIPAA marketing risk checks, event sponsorship revenue. By RubySky Digital, Nashville.
Eu ai act hitl oversight skill
jovd83/eu-ai-act-hitl-monitor-skill/eu-ai-act-hitl-oversight-skill Skill
no license0★ repoDesigns and validates human-oversight controls, handoff contracts, and review flows for EU AI Act-aligned agent systems.
CodedVibesX/byoc-preflight/plugins/byoc-preflight/skills/preflight Skill
0★ repoA Ryvn CLI agent skill that gates regulated BYOC deployments before they ship
Throughproof/throughproof/skills/compliant-logging Skill
0★ repoFree, portable AI-agent skills that write compliant code (audit logging, access control, encryption) mapped to SOC 2, ISO 27001, PCI-DSS & HIPAA at once. Works in Claude Code, Cursor, Copilot, Gemini & Antigravity.
sarfaraz-munir/Claude-Code-Cyber-agents/.claude/skills/ciso-ai-security Skill
0★ repoHierarchical CISO AI agent swarm for Claude Code — 10 specialist agents covering risk governance, compliance, threat intelligence, vulnerability management, incident response, and AI security (OWASP LLM Top 10 / MITRE ATLAS). Includes MCP tools, Claude Code skills etc.
thegeekybeng/architecture-governance/skills/ai-compliance-framework Skill
0★ repoAI architecture governance skills — TOGAF-mapped docs, deterministic compliance verification, and CWE/OWASP-cited code audits for any AI agent
satishTheLegend/risk-register-csf Skill
0★Claude Code skill: a solo security program as durable artifacts — a living risk register, NIST CSF 2.0 self-assessment, and a lightweight incident-response plan. The right-sized GRC slice, no SOC2 ceremony.
matematicsolutions/awesome-matematic-skills-en/ai-governance/skills/eu-ai-act-triage-en Skill
0★ repoEnglish hub of method-neutral legal AI skills (verification core, content quality, EU law) - bundle model. Polish-jurisdiction skills live in awesome-matematic-skills-pl.
AIops-tools/Compliance-AIops/skills/compliance-aiops Skill
0★ repoGoverned compliance evidence from AIops audit trails: HIPAA/PCI-DSS/SOC2/GDPR, hash-chain-sealed, 15 MCP tools (preview)
Ansvar-Systems/regulatory-threat-model-skill Skill
no license0★Agent skill: server-enforced STRIDE + LINDDUN threat modeling with cited EU security-obligations mapping via the Ansvar Gateway MCP connector
cycoresecure/grc-skills/skills/compliance-calendar Skill
no license0★ repoGRC skills for Claude Code and AI agents. SOC 2, HIPAA, ISO 27001 — field-tested by Cycore Secure.
datakoot/regulatory-intel-mcp/com.datakoot/regulatory-intel-mcp MCP server
0★ repoUS Federal Register for AI agents: rules, notices and executive orders. No API keys.
0xsims/rubric-mcp-server/io.github.0xsims/rubric-protocol MCP server
no license0★ repoAI compliance attestation for EU AI Act, SR 11-7, HIPAA. Free local tier, no key required.
CSOAI-ORG/eu-ai-act-compliance-mcp/io.github.CSOAI-ORG/eu-ai-act-compliance-mcp MCP server
0★ repoEu Ai Act Compliance MCP Server by MEOK AI Labs
CSOAI-ORG/hipaa-compliance-mcp/io.github.CSOAI-ORG/hipaa-compliance-mcp MCP server
0★ repohipaa-compliance-mcp MCP server by MEOK AI Labs
CSOAI-ORG/meok-governance-smithery/io.github.CSOAI-ORG/meok-governance-smithery MCP server
0★ repoMEOK Governance Engine - 62 AI governance tools. EU AI Act + NIST + ISO 42001 + crosswalks. Most
CSOAI-ORG/meok-eu-ai-act-art-13-ifu-mcp/io.github.CSOAI-ORG/meok-eu-ai-act-art-13-ifu-mcp MCP server
no license0★ repoMEOK EU AI Act Article 13 Instructions for Use generator — provider-side IFU with 7 mandatory Art
Meok eu ai act art 26 fria mcp
CSOAI-ORG/meok-eu-ai-act-art-26-fria-mcp/io.github.CSOAI-ORG/meok-eu-ai-act-art-26-fria-mcp MCP server
no license0★ repoMEOK EU AI Act Article 26(9) Fundamental Rights Impact Assessment generator. Auto-generates FRIA
CSOAI-ORG/nist-rmf-ai-mcp/io.github.CSOAI-ORG/nist-rmf-ai-mcp MCP server
0★ repoNist Rmf Ai MCP Server by MEOK AI Labs
CSOAI-ORG/pci-dss-mcp/io.github.CSOAI-ORG/pci-dss-mcp MCP server
0★ repopci-dss-mcp MCP server by MEOK AI Labs
CSOAI-ORG/soc2-compliance-ai-mcp/io.github.CSOAI-ORG/soc2-compliance-ai-mcp MCP server
0★ repoSoc2 Compliance Ai MCP Server by MEOK AI Labs
Regulatory & Compliance Intelligence MCP
FoundryNet/compliance-mcp/io.github.FoundryNet/compliance-mcp MCP server
0★ repoRegulatory compliance, FDA recalls, federal register, enforcement actions & comment deadlines.
Data Compliance Classifier MCP
OjasKord/data-compliance-mcp/io.github.OjasKord/data-compliance-mcp MCP server
0★ repoClassify data safety before storing or sharing. GDPR, HIPAA, PCI-DSS, CCPA. AI-powered.
PiQrypt/piqrypt-mcp-server/io.github.PiQrypt/audit-trail MCP server
0★ repoCryptographic audit trail for AI agents. Sign, verify, export. GDPR/HIPAA/EU AI Act.
Esheria Regulatory Intelligence
esherialabs/esheria-python/io.github.esherialabs/esheria MCP server
0★ repoCitation-backed regulatory intelligence tools for explicit multi-jurisdiction packs
Verdict — Compliance for AI-Generated Code
getverdict-ai/releases/io.github.getverdict-ai/verdict MCP server
no license0★ repoCompliance verdicts for AI-generated code. SOC 2, HIPAA, HITRUST for healthcare IT.
governmyai/mcp-server/io.github.governmyai/mcp-server MCP server
0★ repoAI compliance obligations across EU AI Act, ISO 42001, Colorado AI Act, NIST, HIPAA, SOX, FTC
guptaprakhariitr/indian-regulatory-mcp/io.github.guptaprakhariitr/indian-regulatory-mcp MCP server
no license0★ repoSEBI orders, RBI notifications, MCA filings, NSE/BSE announcements, AMFI NAV.
jellewas/eu-audit-mcp/io.github.jellewas/eu-audit-mcp MCP server
0★ repoTamper-evident audit trail MCP server for EU AI Act & GDPR compliance.
mdfifty50-boop/compliance-shield-mcp/io.github.mdfifty50-boop/compliance-shield MCP server
no license0★ repoZATCA, UAE CT, EU AI Act regulatory compliance for AI agents
pipeworx-io/mcp-nist-beacon/io.github.pipeworx-io/nist-beacon MCP server
0★ repoNIST Randomness Beacon v2 — signed public random pulses every 60s.
pipeworx-io/mcp-nist-standards/io.github.pipeworx-io/nist-standards MCP server
0★ repoNIST Standards MCP pack
pipeworx-io/mcp-regulatory-catalysts/io.github.pipeworx-io/regulatory-catalysts MCP server
0★ repoRegulatory Catalysts MCP — high-value biotech regulatory calendar events (keyless).
richbile/obsidian-regulatory-mcp/io.github.richbile/obsidian-regulatory-mcp MCP server
0★ repoVerified, tier-0 regulatory data for AI across 850+ official sources and 50+ jurisdictions.
rival-intelligence/rival-regulatory-toolkit/io.github.rival-intelligence/rival-regulatory-toolkit MCP server
0★ repoRead-only regulatory source retrieval, citation tracing, authority metadata, and recent filings.